Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67231

Опубликовано: 23 сент. 2026
Источник: redhat
CVSS3: 8.1

Описание

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun Attacker knows or can guess the {Issuer, Serial} of at least one whitelisted cert (non-secret; exposed via CLI/logs/any cert copy). This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

A flaw was found in RabbitMQ. The trust-store plugin incorrectly validates client certificates by only matching the issuer name and serial number, rather than using the full certificate for path validation. This allows a remote attacker, who knows the issuer name and serial number of a whitelisted certificate, to bypass Transport Layer Security (TLS) client authentication by presenting a forged self-signed certificate. This could lead to unauthorized access to the RabbitMQ messaging and streaming broker.

Отчет

Important: This flaw in RabbitMQ's trust-store plugin allows a TLS client-authentication bypass. An attacker can connect with a forged self-signed certificate if the rabbitmq_trust_store plugin is enabled and used for TLS verification, and the attacker knows the Issuer DN and serial number of a whitelisted certificate. This bypass could lead to unauthorized access to RabbitMQ resources.

Меры по смягчению последствий

For affected community projects where the rabbitmq_trust_store plugin is enabled, disable the plugin if it is not essential for operations. If the plugin is required, ensure that whitelisted certificates are managed securely and their Issuer DN and serial numbers are not publicly exposed or easily guessable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imageshi/rabbitmqNot affected
Red Hat Hardened Imagesrabbitmq-server4.2Not affected
Red Hat Hardened Imagesrabbitmq-server4.3Not affected
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverNot affected
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2539781rabbitmq: rabbitmq-server: RabbitMQ: Trust-store whitelist by Issuer+Serial only

8.1 High

CVSS3

Связанные уязвимости

ubuntu
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fu...

nvd
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun A

msrc
4 дня назад

RabbitMQ: Trust-store whitelist by Issuer+Serial only

debian
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...

github
3 месяца назад

Trust-store whitelist by Issuer+Serial only

8.1 High

CVSS3